Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • OneOdio Focus A1 Pro review
    • The 11 Best Fans to Buy Before It Gets Hot Again (2026)
    • A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)
    • ‘Euphoria’ Season 3 Release Schedule: When Does Episode 2 Come Out?
    • Francis Bacon and the Scientific Method
    • Proxy-Pointer RAG: Structure Meets Scale at 100% Accuracy with Smarter Retrieval
    • Sulfur lava exoplanet L 98-59 d defies classification
    • Hisense U7SG TV Review (2026): Better Design, Great Value
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Sunday, April 19
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»OpenClaw gives users yet another reason to be freaked out about security
    News

    OpenClaw gives users yet another reason to be freaked out about security

    Editor Times FeaturedBy Editor Times FeaturedApril 3, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    For greater than a month, safety practitioners have been warning in regards to the perils of utilizing OpenClaw, the viral AI agentic device that has taken the event group by storm. A not too long ago mounted vulnerability gives an object lesson for why.

    OpenClaw, which was launched in November and now boasts 347,000 stars on Github, by design takes management of a consumer’s laptop and interacts with different apps and platforms to help with a bunch of duties, together with organizing information, doing analysis, and buying on-line. To be helpful, it wants entry—and plenty of it—to as many sources as doable. Telegram, Discord, Slack, native and shared community information, accounts, and logged in periods are solely a few of the supposed sources. As soon as the entry is given, OpenClaw is designed to behave exactly because the consumer would, with the identical broad permissions and capabilities.

    Extreme affect

    Earlier this week, OpenClaw builders launched safety patches for 3 high-severity vulnerabilities. The severity ranking of 1 particularly, CVE-2026-33579, is rated from 8.1 to 9.8 out of a doable 10 relying on the metric used—and for good cause. It permits anybody with pairing privileges (the lowest-level permission) to realize administrative standing. With that, the attacker has management of no matter sources the OpenClaw occasion does.

    “The sensible affect is extreme,” researchers from AI app-builder Blink wrote. “An attacker who already holds operator.pairing scope—the bottom significant permission in an OpenClaw deployment—can silently approve machine pairing requests that ask for operator.admin scope. As soon as that approval goes via, the attacking machine holds full administrative entry to the OpenClaw occasion. No secondary exploit is required. No consumer interplay is required past the preliminary pairing step.”

    The submit continued: “For organizations operating OpenClaw as a company-wide AI agent platform, a compromised operator.admin machine can learn all related knowledge sources, exfiltrate credentials saved within the agent’s ability surroundings, execute arbitrary device calls, and pivot to different related providers. The phrase ‘privilege escalation’ undersells this: the result is full occasion takeover.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)

    April 19, 2026

    Google is in talks with Marvell Technology to develop a memory processing unit that works alongside TPUs, and a new TPU for running AI models (Qianer Liu/The Information)

    April 19, 2026

    At the Beijing half-marathon, several humanoid robots beat human winners by 10+ minutes; a robot made by Honor beat the human world record held by Jacob Kiplimo (Reuters)

    April 19, 2026

    A look at the AI nonprofit METR, whose time-horizon metrics are used by AI researchers and Wall Street investors to track the rapid development of AI systems (Kevin Roose/New York Times)

    April 19, 2026

    Binance and Bitget to probe a rally in RaveDAO’s RAVE token, which surged 4,500% in a week, after ZachXBT alleged RAVE insiders engineered a large short squeeze (Francisco Rodrigues/CoinDesk)

    April 19, 2026

    Mistral, which once aimed for top open models, now leans on being an alternative to Chinese and US labs, says it’s on track for $80M in monthly revenue by Dec. (Iain Martin/Forbes)

    April 19, 2026

    Comments are closed.

    Editors Picks

    OneOdio Focus A1 Pro review

    April 19, 2026

    The 11 Best Fans to Buy Before It Gets Hot Again (2026)

    April 19, 2026

    A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)

    April 19, 2026

    ‘Euphoria’ Season 3 Release Schedule: When Does Episode 2 Come Out?

    April 19, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Apple researchers detail the limitations of top LLMs and large reasoning models, like o3, especially on problems of medium to high complexity (Gary Marcus/Marcus on AI)

    June 9, 2025

    Online singing helps ease chronic breathlessness in lung disease

    October 13, 2025

    South Australian startup Splose raises $46 million in another Series A

    February 9, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.